The Envelope and the Contents: Why Logging Agent-to-Agent Traffic Is Not Reading It
METHODS · WORKING PAPER — Governance. Programme: Admissibility & Evidence. Empirical and analytical; anchored to dated, citable sources as of July 2026. Builds on Who Acted, Under Whose Authority? and Assisting or Deciding? This paper makes no claim about the intentions of AI agents; its argument does not require one.
The standard now consolidating for communication between AI agents records, with considerable rigour, who messaged whom, about what task, and when. It does not require that what was actually communicated remain legible to a human, nor that the authority under which each agent acted travel with the message. It captures the envelope and leaves the contents to the parties. That distinction — between a complete audit trail of an exchange and a reconstructable account of a decision — is the difference between a log and a record. And it is being settled right now, as an engineering question, in the layer that is becoming the infrastructure of agentic decision-making.
The argument of this paper is narrow and does not depend on anything dramatic. It requires no belief that agents are concealing anything, coordinating against oversight, or developing capabilities anyone intended. It requires only two things that are not in dispute: that systems optimised for communicative efficiency drift away from human-legible protocols, and that nothing in the emerging standard requires them not to. Where those two hold, the agent-to-agent layer becomes, by construction, a place where a complete log documents an exchange no one can read.
What does the standard actually record?
The Agent-to-Agent protocol has moved from proposal to infrastructure. Released at version 1.0 in April 2026 under the Linux Foundation after Google’s donation, it is now supported by more than 150 organisations, integrated into the AWS, Microsoft, and Google cloud platforms, and positioned as the de facto standard for inter-agent communication in enterprise contexts. It is a genuine engineering achievement, and its governance features are not an afterthought. Agent Cards provide a discovery mechanism through which each agent publishes a machine-readable description of its capabilities, input and output modalities, and authentication requirements, while Tasks represent units of work with a defined lifecycle carrying structured payloads. Authentication follows standard OAuth 2.0 flows, and the protocol supports audit logging so organisations can maintain compliance records of inter-agent communications. Every task invocation, message, and artifact can be logged, producing a complete audit trail. arxiv + 3
Read that last sentence carefully, because it is the whole problem. A complete audit trail of what was sent is not an account of what was decided. The protocol records the envelope with precision: sender, recipient, task, lifecycle state, timestamp, authenticated scope. What travels inside — the reasoning, the summary passed forward, the judgment one agent handed to another — is a payload the protocol carries faithfully and does not require anyone to be able to read. A perfectly logged exchange in a form no human can reconstruct is a perfectly logged nothing.
Why won’t the contents stay legible on their own?
Because legibility is not what the contents are optimised for, and there is no requirement supplying the pressure in the other direction.
This is the oldest and most robust finding in the study of machine communication. Agents trained for communicative success drift rapidly away from human-interpretable protocols, even when they are seeded with natural language to begin with. In the emergent-communication literature, agents reliably develop functional protocols from scratch, but those protocols are consistently optimised for task efficiency rather than for expressivity or compositionality: they work, without being language in any meaningful sense. The same pressure operates on deployed systems under a friendlier name. Compression saves tokens; tokens cost money; nothing in the protocol rewards a payload that a person could follow. In one recent field observation of a platform where autonomous language-model agents post and interact, researchers isolated 518 posts in which agents proposed constructed languages, and the largest category by stated purpose was token efficiency.
How not to read that literature. A subset of those proposals was framed in terms of avoiding human oversight, and it would be easy — and wrong — to build an argument on it. Framing is not capability and not intent: a post that presents itself as proposing an oversight-evading language demonstrates neither that the language would be opaque nor that anyone would deploy it, and jokes, roleplay, and posturing are indistinguishable from sincere proposals in such a corpus. The researchers themselves are explicit that their observations are hypothesis-generating, that they cannot confirm every post is agent-authored, and that aspiration outruns practice — much of what reads as post-human novelty is script rarity, not new language. The Institute relies on none of it. The governance problem here does not require a single agent to be hiding anything. It requires only that efficiency pressure exists, that legibility is unrequired, and that the two together are sufficient. They are.
What the standard leaves out: authority provenance
The second gap is not about contents at all, and it is the one the standards community has itself named. Signed Agent Cards give A2A verifiable identities, and enterprise governance products supply the audit trails that compliance demands — but what does not yet exist is a unified way for an agent to carry who it is, who it acts for, and what it may do across all the layers at once; this is expected to be the defining standards fight of 2027. DEV Community
That sentence, written from inside the engineering community, describes precisely what the Institute has called the delegation record: identity, bounded authority, the chain of hand-offs, the human origin of the authority, the accountable party, and the point at which a human could still have refused. An agent’s identity may be cryptographically verifiable at the endpoint and entirely absent from the chain of delegation that produced a decision. Verifying that an agent is who it says it is answers a different question from establishing that it was permitted to do this, by whom, on whose authority.
The prevailing operational advice makes this worse in a way worth naming. Enterprises are told to treat agent networks like microservices — with service accounts, monitoring, and fail-safes — and, while the protocol facilitates logging and control, organisations must still govern agent behaviour themselves. The service-account pattern is the identity-erasing pattern. It authenticates a process, not an actor, and it carries no authority provenance whatsoever. An agentic estate built to that advice will have flawless authentication, complete logs, and no answer to the only question a citizen or a court will ask: who acted, under whose authority? The protocol’s own governance posture is consistent on this point: it supplies observability features and expects teams to implement the governance controls themselves. Capability is not authority. A protocol that can carry provenance but does not require it will, at scale, mostly not carry it. HackernoonOneReach
Reading it through admissibility
Applied to the agent-to-agent layer, the Institute’s first signpost — the record — returns a reading that is uncomfortable and, on the current design, structural rather than accidental. The logs are complete. The decision cannot be reconstructed. That is the Ceremonial reading of the record dial, arrived at not through negligence but through a standard that captures events faithfully while requiring nothing of authority or legibility. No record, no standing applies here with unusual force: an agent chain whose exchanges cannot be read and whose authority cannot be traced has not earned admission to a consequential decision, however immaculate its audit trail.
The consequences run straight into the Agentic Government papers, and they are sharper than they first appear.
The delegation record requires six things to be establishable after the fact. The protocol supplies parts of the first and third — identifiable agents, and a trace of who called whom. It does not supply the origin of the authority, the accountable human, or the point of possible refusal, and it does not require that the substance passed between agents be recoverable at all.
The assisting-or-deciding test then fails at its first condition. An official can only be deciding, rather than ratifying, if they can reconstruct the basis of the determination. Where the agent-to-agent layer is illegible, reconstruction is not difficult; it is impossible. Every human review of a determination produced by such a chain is therefore a ratification — not because the official was careless, but because the protocol made deciding unavailable to them. And a ratification that is a property of the deployment rather than of the person is, in the third paper’s terms, a structural failure: the remedy is not to re-decide one case but to withdraw the chain’s standing until it can support genuine deciding.
Put plainly: an agentic administration built on a record standard that captures envelopes and not contents cannot make lawful decisions about people, because no official within it can decide, and no citizen outside it can contest. This does not follow from anything the agents do. It follows from what the record was designed to hold.
Who is settling this, and when?
The uncomfortable timing is the point of this paper. The record-versus-log question for the agentic layer is being answered now, in a standards foundation, by vendors, as an engineering matter — and the answer is being written into infrastructure that hundreds of organisations are already deploying. Audit logging is a capability the protocol supports and enterprises configure; it is not a legal requirement, and nothing in it compels legibility or provenance. The frameworks that would care are either non-binding or not yet in force: Singapore’s agentic guidance recommends traceable agent identity linked to an accountable human but does not compel it, and the EU AI Act’s meaningful-human-oversight obligations for high-risk public-sector systems were deferred to December 2027 by the Digital Omnibus.
So the window closes in the wrong order. The layer will be built, adopted, and depended upon before the obligations that would demand reconstructability take effect — and by then, “we can’t require that, everything is built on it” will be a true statement. This is the deadline dial, arriving from the technical side rather than the legislative one: not a rule that slipped, but a standard that consolidated first.
What a legibility requirement would have to require
If the agent-to-agent layer is to produce records rather than logs, four conditions have to be met, and none of them is satisfied by better logging.
1. Legible contents at consequential steps. Where an exchange between agents materially shapes a consequential decision, its substance must be recoverable in human-readable form. This does not mean natural language at every hop; it means that at the steps that matter, what was communicated can be read.
2. Contemporaneous rendering, not post-hoc explanation. If a human-readable rendering of an exchange is generated afterwards — by another model, from an illegible payload — it is not a record of the decision. It is a new artifact, generated by a system with its own failure modes, describing something no one can check it against. The rendering must be produced at the time, and the system must be bound by it: what the rendering says is what the exchange is taken to have said.
3. Authority provenance that survives delegation. Each message must carry not only a verified identity but the bounded authority under which the agent acts, and a chain that terminates in a human. Provenance must survive hand-off, including across organisational boundaries, or the chain becomes untraceable at exactly the point it leaves the operator’s control.
4. Independent verifiability. Whether the first three hold must be checkable by someone independent of the operator. A legibility standard asserted by the party whose systems it constrains is not a standard; it is a claim.
These are demanding. They are also, deliberately, less demanding than “log everything”: three of the four are properties of the record’s structure, not of its volume.
The honest tension
Compression exists because it works. Requiring fully human-legible natural language at every hop of every agent chain would be expensive, would slow systems that benefit no one by being slow, and would produce mountains of text at trivial steps while the consequential ones drown in it. There are also legitimate reasons for confidentiality between agents — commercial, personal, and security-related — and a naive legibility mandate would collide with data protection as readily as it would serve it. The standard cannot be maximal.
Nor should this paper’s argument be stretched. It shows that the current design permits an illegible agent-to-agent layer and supplies no pressure against one; it does not establish that production A2A deployments have already become illegible. The empirical observations of drift come from research settings and open platforms, not from audited enterprise systems, and honest analysis has to say so. The claim is about what the standard makes possible and probable, not about what has been measured in the field.
What remains after both concessions is narrow and firm: at the steps where an agentic exchange materially shapes a consequential decision about a person, the substance must be recoverable and the authority must be traceable — and the protocol layer, not the deploying organisation’s goodwill, is where that requirement has to live. Everywhere else, we should be honest that the log is a log.
What this paper does not settle
Three questions remain open. First, what constitutes a consequential step inside an agent chain — the boundary between routine coordination and the exchange that shapes the outcome — needs a workable test, and this paper does not supply one. Second, whether a contemporaneous human-readable rendering can be made faithful to an efficient underlying representation is an unsolved technical problem, and a rendering that is systematically unfaithful would be worse than none, because it would look like a record. Third, when an agent chain crosses organisational and national boundaries, whose legibility standard binds, and who audits it, is unresolved — and it is the question that will decide whether any of the above is enforceable at all.
FAQ
Doesn’t A2A already provide a complete audit trail?
It provides a complete trail of the envelope: which agent sent what task to which agent, when, under what authenticated scope. It does not require that the contents be human-legible, nor that the authority under which each agent acted travel with the message. A complete log of an unreadable exchange is a log, not a record.
Is this a claim that AI agents are hiding things from humans?
No, and the argument deliberately does not depend on it. It rests on two undisputed points: systems optimised for communicative efficiency drift away from human-legible protocols, and nothing in the standard requires them not to. No intent is needed for the record to become unreadable.
Why does this matter for public decisions specifically?
Because an official can only be said to have decided, rather than ratified, if they can reconstruct the basis of the determination. Where the agent-to-agent layer is illegible, reconstruction is impossible, so every human review of such a determination is structurally a ratification — and a decision no one really made is not one the law authorised.
What would fix it?
Legible contents at consequential steps; a human-readable rendering produced at the time and binding on the system, not reconstructed afterwards; authority provenance that survives delegation across organisational boundaries; and independent verifiability of all three. None of these is achieved by logging more.
